ISTA 2026Fest Edition

Sofia Event Center

Tickets on sale

Latest InsightISTA 2026 adds Nikolay Avramov, who works on the test suites that still have to run in a year

DecisionsSecurity & Compliance

AWS and Cisco Just Automated MCP Server Security Scanning. Here's What That Actually Means for Your Agent Sprawl.

AWS and Cisco just automated security scanning for MCP servers and AI agents, solving the visibility nightmare that's been keeping security teams up at night. Here's what this actually means for your growing agent sprawl and compliance headaches.

The Model Context Protocol (MCP) went from “interesting experiment” to “enterprise headache” in about six months. Since Anthropic released it in November 2024, organizations have gone from zero to dozens (sometimes hundreds) of MCP servers connecting AI agents to databases, APIs, and internal systems. The Agent-to-Agent (A2A) Protocol followed in April 2025, letting autonomous agents talk to each other without human intervention. Now AWS and Cisco have announced an integration that automatically scans these components for security vulnerabilities before they go live.

In Brief

AWS and Cisco AI Defense have integrated automated security scanning into the AI Registry, an open-source control plane for MCP servers, A2A agents, and Agent Skills. The system scans every registered component for vulnerabilities, prompt injection patterns, and compliance violations, automatically disabling anything flagged until an administrator reviews it.

For teams managing growing agent deployments under SOX or GDPR requirements, this addresses the audit trail gap that manual reviews cannot close at scale.

For teams already wrestling with agent governance questions, ISTA 2026 in September is where Bulgarian engineering leads are comparing notes on exactly these problems. Early bird tickets are available.

The Visibility Problem Nobody Wants to Admit

Security teams have a dirty secret: they often have no idea how many MCP servers are running in their infrastructure. Teams add servers ad-hoc across cloud and on-premises environments. A developer spins up a database connector here, an API bridge there.

Before anyone notices, the organization has 47 MCP servers, 12 A2A agents, and zero centralized inventory.

The AWS-Cisco integration attacks this through the AI Registry, which functions as a single control plane where every MCP server, AI agent, and Agent Skill must be registered. Registration is not optional decoration. Components that are not registered cannot be discovered by other agents in the ecosystem.

How the Scanning Actually Works

When a new MCP server or A2A agent is registered, three scanning layers activate:

YARA Analyzer handles pattern-based detection for known threats: SQL injection, command injection, hardcoded credentials. This is fast, deterministic scanning that catches the obvious problems.

LLM Analyzer uses Amazon Bedrock’s frontier models for semantic analysis. This layer examines tool logic and agent behavior to identify sophisticated threats that pattern matching would miss.

Cisco AI Defense Proprietary Scanners (MCP Scanner, A2A Scanner, Skills Scanner) combine threat intelligence with deep code analysis. The A2A Scanner specifically analyzes agent card metadata for identity spoofing, prompt injection in metadata fields, data exfiltration endpoints, and SSRF patterns.

If any scanner finds issues, the component is automatically disabled with a “security-pending” tag. It stays disabled until an administrator reviews the detailed security report and explicitly approves it.

The Compliance Angle That Actually Matters

Manual security reviews for MCP servers reportedly add weeks to each AI application deployment. That backlog grows faster than teams can clear it. The automated scanning approach transforms this into a self-service workflow: developers register components, scanning happens automatically, clean components go live immediately, flagged components queue for human review.

For SOX and GDPR compliance, the system maintains complete security audit history. Every scan result, every approval decision, every component state change is logged. When auditors ask “which AI agents had access to customer data on March 15th, and who approved that access?”, the answer exists in a queryable format.

What This Means for Bulgaria

Bulgarian engineering teams working with EU clients face a specific pressure: GDPR compliance requires demonstrable control over data access, and AI agents that connect to customer databases create audit exposure that is difficult to quantify. The automated scanning and audit trail capabilities address this directly.

For teams building AI-powered products for export, the integration with ServiceNow and Slack (mentioned in the AWS announcement) means security findings can flow into existing incident response workflows. This matters for ISO 27001 certification processes, where demonstrating automated security controls strengthens the compliance posture.

Practical next steps: if your team is deploying MCP servers, check whether your current inventory process would survive an audit. If the answer is “we would need to grep through deployment logs,” the AI Registry approach is worth evaluating.

Automation transforms compliance from bureaucratic burden into competitive advantage.

The Open Architecture Bet

The AI Registry uses the same REST API specification as Anthropic’s official MCP Registry. This is not accidental. AWS and Cisco are betting that MCP becomes the dominant protocol for agent-to-tool communication, and they want their security layer to be the default choice regardless of which MCP implementation organizations adopt.

The registry supports federation with other MCP deployments, meaning organizations can maintain their own registries while still benefiting from centralized security scanning. Central IT teams can query the registry programmatically to discover available MCP servers and agents, supporting threat detection at scale.

The Gaps That Remain

The announcement does not address runtime monitoring. Scanning happens at registration time, but agents can behave differently in production than their metadata suggests. A clean scan does not guarantee clean behavior.

The system also assumes organizations will actually register their MCP servers. Shadow IT is a real phenomenon. Developers who want to move fast may spin up unregistered servers, bypassing the entire governance layer. The security model depends on organizational discipline that many teams lack.

Finally, the scanning relies on Cisco AI Defense’s threat intelligence. Organizations without Cisco AI Defense subscriptions can still use the AI Registry, but they lose access to the proprietary scanners. The YARA and LLM analyzers remain available, but the deepest threat detection requires the commercial integration.

Dig Deeper

AWS announcement: Securing AI agents with Cisco AI Defense covers the full technical architecture and integration patterns.

AI Registry GitHub repository (referenced in the announcement) contains the open-source implementation.

Anthropic’s MCP specification provides the protocol foundation that the AI Registry builds upon.

This Week’s Take

The AWS-Cisco integration is not revolutionary, but it is necessary. MCP adoption outpaced security tooling, and organizations have been flying blind. Automated scanning with audit trails is table stakes for enterprise AI deployment.

The real question is whether this becomes the default governance layer or just one option among many. Given AWS’s distribution reach and Cisco’s enterprise security credibility, the odds favor adoption. Teams deploying MCP servers today should evaluate this integration before their audit exposure becomes a compliance incident.

ISTA 2026 · 15 October 2026

One day in October. A year of engineering knowledge.